Re: [squid-users] Login-ID and Password Revealed

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Fri, 03 Jan 2003 12:16:43 +0100

http://www.squid-cache.org/Versions/v2/2.5/bugs/, but if you are using
cahchemgr from the 20030102 snapshot then you should already have this.

If webmin uses a custom cachemgr login interface then a similar change
may need to be applied to webmin.

Regards
Henrik

Rocky wrote:
>
> Hi,
>
> I installed squid-2.5.STABLE1-20030102 and Webmin
> 1.050 yesterday on Solaris 8.
>
> Whenever I key in my Manager name and Password at the
> Cache Manager Interface of webmin, then click on the
> Continue button, the next thing I noticed is my
> User_Name and Password appears unencrypted at the URL,
> such as :
>
> http://10.9.3.155:10000/squid/cachemgr.cgi?host=localhost&port=3128&user_name=root&passwd=squid123
>
> How can I prevent these 2 important info from
> showing up at the URL ?
>
> __________________________________________________
> Do you Yahoo!?
> Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
> http://mailplus.yahoo.com
Received on Fri Jan 03 2003 - 04:29:47 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:12:26 MST